CVE-2014-0545 is a critical memory address disclosure vulnerability affecting Adobe Flash Player, AIR, and AIR SDK across Windows, OS X, and Linux platforms. This flaw allows attackers to bypass Address Space Layout Randomization (ASLR) protection, a key security mechanism, through unspecified vectors. With a CVSS score of 10.0, this vulnerability presents a severe risk, enabling full compromise of confidentiality, integrity, and availability due to its network-exploitable, low-complexity nature requiring no authentication. While there is no public exploit code available (Metasploit, Nuclei, ExploitDB), SecurityWeek reported that this vulnerability was leveraged in targeted attacks, indicating active exploitation in the wild. Community discussion and media coverage are minimal, suggesting limited public awareness despite its critical impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 13.0.0.231CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
13.0.0.182CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:13.0.0.182:*:*:*:*:*:*:* | ||
13.0.0.201CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:13.0.0.201:*:*:*:*:*:*:* | ||
13.0.0.206CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:13.0.0.206:*:*:*:*:*:*:* | ||
13.0.0.214CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:13.0.0.214:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.